Update uses:
update 0.7.4
├─┬ base-cli-process 0.1.19
│ ├─┬ base-config-process 0.1.9
│ │ └─┬ base-config-schema 0.1.24
│ │ └─┬ base-pkg 0.2.5
│ │ └─┬ expand-pkg 0.1.9
│ │ └── defaults-deep 0.2.4
│ └─┬ base-pkg 0.2.5
│ └─┬ expand-pkg 0.1.9
│ └── defaults-deep 0.2.4
├─┬ base-config-process 0.1.9
│ └─┬ base-config-schema 0.1.24
│ └─┬ base-pkg 0.2.5
│ └─┬ expand-pkg 0.1.9
│ └── defaults-deep 0.2.4
└─┬ base-generators 0.4.6
└─┬ base-pkg 0.2.5
└─┬ expand-pkg 0.1.9
└── defaults-deep 0.2.4
Defaults-deep@0.2.4, has a critical vulnerability (GHSA-pjxw-22xf-6pwc) for which there seems to be no current fix. I have contacted expand-pkg, but I thought you should be informed too.
Update uses:
update 0.7.4
├─┬ base-cli-process 0.1.19
│ ├─┬ base-config-process 0.1.9
│ │ └─┬ base-config-schema 0.1.24
│ │ └─┬ base-pkg 0.2.5
│ │ └─┬ expand-pkg 0.1.9
│ │ └── defaults-deep 0.2.4
│ └─┬ base-pkg 0.2.5
│ └─┬ expand-pkg 0.1.9
│ └── defaults-deep 0.2.4
├─┬ base-config-process 0.1.9
│ └─┬ base-config-schema 0.1.24
│ └─┬ base-pkg 0.2.5
│ └─┬ expand-pkg 0.1.9
│ └── defaults-deep 0.2.4
└─┬ base-generators 0.4.6
└─┬ base-pkg 0.2.5
└─┬ expand-pkg 0.1.9
└── defaults-deep 0.2.4
Defaults-deep@0.2.4, has a critical vulnerability (GHSA-pjxw-22xf-6pwc) for which there seems to be no current fix. I have contacted expand-pkg, but I thought you should be informed too.